The Financial Register.

Inward fraud & financial crime, explained for Gen Z

patternson
Credit: News 24 News 24

Data Breaches

Services Australia left its security inbox unchecked before AI breach, Paterson says

The shadow defence minister says the agency took four days to alert Australia's cyber experts once it finally read the report.

By Miko Santos · 10:09 AEST · 27 September 2026

Services Australia was not watching the inbox it set up for the public to report security holes in its systems, and took four days to alert the Australian Signals Directorate once it did, Shadow Defence Minister James Paterson said on Sunday.

Paterson told News 24's Sunday Agenda the breach of the agency's statistics portal by an OpenAI agent this month should be treated as a warning.

"It's extraordinary to me that Services Australia wasn't constantly monitoring the inbox, which they set up themselves, and they asked the public to tell them about cyber security vulnerabilities of their networks," Paterson said.

"When they finally did check the inbox, it took them four days before they informed the Australian Signals Directorate, our cyber security experts."

He said Medicare itself was not hacked. The data came from a Services Australia statistics portal and had been prepared for public release to academics and researchers.

That did not make it harmless.

"It could be more sensitive data, it could be more sensitive network, it might be Medicare actually next time, or it could be the ATO or it could be a critical infrastructure provider," he said.

Paterson said his understanding was that the Prime Minister's office had the information for five or six days before Prime Minister Anthony Albanese announced it. He accused Albanese of picking the day Sam Altman addressed the United Nations to make the announcement.

Deputy Prime Minister Richard Marles told the same program earlier that the incident was serious but its impact was minor.

Paterson credited OpenAI for telling the government, the first time Australia has been notified of a breach of this kind by an AI agent. He doubted it was the first breach.

"I guarantee you that if this was an AI company based in the People's Republic of China and it engaged in a breach of Australian government networks, they will not be sending an email to any inbox to let us know," he said.

He wants Australia to secure training investment from leading US AI companies, which he said would guarantee access to their models and a say in how AI is regulated, including mandatory notification of incidents like this one.

"Right now that doesn't happen, but it should," he said.